2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-3933MEDIUM5.4The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow...
CVE-2022-3930MEDIUM6.5The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to chan...
CVE-2022-3919MEDIUM4.8The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users s...
CVE-2022-3908MEDIUM6.1The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2022-3906MEDIUM4.8The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow...
CVE-2022-3883MEDIUM6.5The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not...
CVE-2022-3882MEDIUM6.5The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not ...
CVE-2022-3881MEDIUM5.7The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Lo...
CVE-2022-3880MEDIUM6.5The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4...
CVE-2022-3879MEDIUM6.5The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authori...
CVE-2022-3862MEDIUM4.8The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which...
CVE-2022-3853MEDIUM5.4Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a w...
CVE-2022-3609MEDIUM4.8The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow...
CVE-2022-45956MEDIUM5.3Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method...
CVE-2022-4421MEDIUM6.1A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t...
CVE-2022-45970MEDIUM5.4Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.
CVE-2022-44648MEDIUM5.5An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to di...
CVE-2022-44647MEDIUM5.5An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to di...
CVE-2022-44532MEDIUM6.5An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Success...
CVE-2022-43518MEDIUM6.5An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful explo...
CVE-2022-42446MEDIUM6.5Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ab...
CVE-2022-42445MEDIUM4.9HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to re...
CVE-2022-37930MEDIUM5.5A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary ...
CVE-2022-37929MEDIUM5.5Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble ...
CVE-2022-37928MEDIUM6.5Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Fla...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now